Disclosed Chromium Security Bugs

CHECK failure: ValueRepresentationIs(input->properties().value_representation(), NodeT::kInputT

#430125749Reporter: 24...@project.gserviceaccount.com
$0
10/15/2025

DCHECK failure in base::FPU::GetFlushDenormals() == isolate->flush_denormals() in local-isolate.cc

#429761781Reporter: 24...@project.gserviceaccount.com
$0
10/15/2025

quickjs:fuzz_compile: Use-of-uninitialized-value in JS_DefineProperty

#449772271Reporter: 87...@developer.gserviceaccount.com
$0
10/12/2025

blink_gif_decoder_fuzzer: CHECK failure: frame.GetStatus() == ImageFrame::kFrameInitialized || frame.GetStatus() == Image

#428754691Reporter: 24...@project.gserviceaccount.com
$0
10/12/2025

libwebp:advanced_api_fuzzer@AdvancedApi.AdvancedApiTest: Crash in RescalerImportRowExpand_SSE2

#449781448Reporter: 87...@developer.gserviceaccount.com
$0
10/11/2025

libwebp:advanced_api_fuzzer@AdvancedApi.AdvancedApiTest: Heap-buffer-overflow in ProcessRows

#447845730Reporter: 87...@developer.gserviceaccount.com
$0
10/11/2025

libwebp:advanced_api_fuzzer@AdvancedApi.AdvancedApiTest: Heap-buffer-overflow in AddGreenToBlueAndRed_AVX2

#447958064Reporter: 87...@developer.gserviceaccount.com
$0
10/11/2025

Permission element inner div with style text-emphasis:꧁; and text-emphasis-position: over right; can be abused if no element in the parent chain has any text-emphasis:꧁; and text-emphasis-position: over right; are set.

#428455319Reporter: sa...@gmail.com
$1,000
10/11/2025

V8 Sandbox Bypass: OOB write in the WasmFullDecoder EndControl handler

#427918760Reporter: vs...@gmail.com
$5,000
10/11/2025

checkstyle:CheckstyleFuzzer: Security exception in com.puppycrawl.tools.checkstyle.grammar.java.JavaLanguageParser.expr

#449346956Reporter: 87...@developer.gserviceaccount.com
$0
10/10/2025
Showing 151-160 of 8802 bugs